PatchSiren cyber security CVE debrief
CVE-2026-80665 Linux CVE debrief
The Linux kernel vulnerability CVE-2026-80665 has been resolved. The KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN issue has been fixed by preparing an external abort before returning from kvm_translate_vncr(). This fix prevents potential aborts in KVM: arm64: nv. The vulnerability was addressed by modifying the kvm_handle_vncr_abort() function to handle 'late' failures on the output of S1 translation. Affected users of the Linux kernel, particularly those using KVM: arm64: nv, should apply the patch to prevent potential aborts. Evidence is limited to the official CVE Program record and NIST NVD detail page. Defenders should verify affected scope, severity, and vendor guidance with these sources. The fix involves preparing an external abort before returning from kvm_translate_vncr(), which helps prevent potential aborts in KVM: arm64: nv.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-28
- Original CVE updated
- 2026-08-29
- Advisory published
- 2026-08-28
- Advisory updated
- 2026-08-29
Who should care
Users of the Linux kernel, particularly those using KVM: arm64: nv, should apply the patch to prevent potential aborts. Operators, platform administrators, vulnerability management teams, and security teams should review system configurations for potential vulnerabilities and monitor for related issues with the Linux kernel. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and check relevant monitoring, detection, and logs for exposed assets that need extra review. Finally, they should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. This involves reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Those impacted are likely those with Linux kernel deployments using KVM: arm64: nv, and should take steps to ensure their configurations are secure and up-to-date with recommended patches and mitigations. Those not directly impacted should still be aware of the vulnerability and ensure their configurations are secure and up-to-date with recommended patches and mitigations. This includes reviewing system configurations for potential vulnerabilities and monitoring for related issues with the Linux kernel. Those with Linux kernel deployments should also consider compensating controls for exposed systems while remediation is scheduled and verified. Finally, they should track exceptions, retest remediated assets, and close the item only after evidence is documented. This involves reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Those impacted are likely those with Linux kernel deployments using KVM: arm64: nv, and should take steps to ensure their configurations are secure and up-to-date with recommended patches and mitigations. Those not directly impacted should still be aware of the vulnerability.
Technical summary
The Linux kernel vulnerability CVE-2026-80665 has been resolved. The KVM: arm64: nv: Inject SEA if kvm_translate_vncr() can't resolve PFN issue has been fixed by preparing an external abort before returning from kvm_translate_vncr(). This fix prevents potential aborts in KVM: arm64: nv and users of the Linux kernel, particularly those using KVM: arm64: nv, should apply the patch. The vulnerability was addressed by modifying the kvm_handle_vncr_abort() function to handle 'late' failures on the output of S1 translation. The fix involves preparing an external abort before returning from kvm_translate_vncr(), which helps prevent potential aborts in KVM: arm64: nv. The vulnerability affects Linux kernel deployments using KVM: arm64: nv, and users should take steps to ensure their configurations are secure and up-to-date with recommended patches and mitigations.
Defensive priority
Apply the patch to prevent potential aborts in KVM: arm64: nv. Monitor for related issues with the Linux kernel.
Recommended defensive actions
- Apply the patch to prevent potential aborts in KVM: arm64: nv
- Monitor for related issues with the Linux kernel
- Review system configurations for potential vulnerabilities
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-08-28T08:16:51.747Z and modified on 2026-08-29T07:16:49.080Z. The NVD entry is currently Received. Evidence is limited to the official CVE Program record and NIST NVD detail page. Defenders should verify affected scope, severity, and vendor guidance with these sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80665 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80665
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80665 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80665
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4ead4def04659739c399bfcb063f8a906194c79f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/53804b6839573c9c6fff5f4cf075d6746267345e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9f3e83345a56280efffe235c65593c7e544c0fcc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.